Yookassa Webhook Flaw Allowed Forging Payment Confirmations via Single Curl Request
A technical audit of a car rental booking service revealed that the Yookassa webhook endpoint accepted payment.succeeded events at face value, allowing forged payment confirmations with a single unauthenticated curl request.
Original vulnerable implementation
The handler in payment_service.py extracted the event type and gateway_payment_id directly from the incoming JSON payload. It performed only one check: whether the gateway_payment_id existed in the local database. If the event type matched payment.succeeded, the payment status was updated and the booking marked as paid. No signature validation, IP filtering, or secondary verification against the Yookassa API was performed.
Because the gateway_payment_id is returned to the client immediately after payment initiation, any user who created a booking could replay the identifier in a forged webhook and complete the transaction without paying.
Why signature checks were not already in place
Yookassa documentation describes an optional Webhook-Signature header using HMAC-SHA256, yet the integration had never configured a webhook_key. The team rejected IP-based allowlisting because traffic passed through reverse proxies, making reliable extraction of the client IP difficult without weakening the trust model. Instead, the fix relies on an authoritative reverse lookup.
Remediation implemented
The corrected handler now treats the incoming webhook solely as a notification trigger. It immediately calls the Yookassa Payments API using the shop ID and secret key to retrieve the current payment state. Status, amount, and currency are taken exclusively from the API response. Mismatches or API failures result in the webhook returning a 5xx status so that Yookassa will retry later. Final statuses are no longer overwritten by subsequent notifications.
A development mode that lacks API credentials retains the original trusting behavior, as no real payments occur in that environment.
Testing and scope of the patch
- test_forged_webhook_ignored_when_gateway_says_pending — forged succeeded event ignored when API reports pending
- test_webhook_amount_mismatch_ignored — status unchanged on amount discrepancy
- test_webhook_confirmed_success_marks_paid — correct transition when API confirms payment
- test_webhook_canceled_marks_failed — cancellation properly reflected
- test_webhook_final_status_not_rewritten — no extra API call for already-final payments
- test_webhook_unknown_payment_ignored — unknown IDs produce no side effects
The PR added 62 lines to the service and 205 lines of tests. Three further improvements—IP allowlisting, signature verification, and removal of double commits—were intentionally left for separate work to keep the security fix minimal and low-risk.
Related articles
Critical Sandbox Bypass Flaw in GitLab AI Gateway Enables Remote Command Execution
GitLab has released patches for a critical vulnerability in its GitLab AI Gateway component that allows authenticated users to bypass sandbox restrictions and execute arbitrary commands. The flaw, tracked as CVE-2026-90970, resides in the custom flow prompt template processing of the Duo Agent Platform and carries a CVSS v3.1 base score of 9.9. Self-hosted deployments are affected, while GitLab’s own hosted AI Gateway service has already been updated. The company urges immediate upgrades to versions 19.4.1, 19.3.2, or 19.2.4. The vulnerability can be triggered under specific conditions by users with access to the Duo Agent Platform through crafted flow configurations.
WebPros Releases Critical Patches for Three Vulnerabilities in cPanel & WHM
WebPros International has published security updates addressing three critical vulnerabilities in its cPanel & WHM hosting management platform. All three issues received the highest severity rating of Critical. The flaws include CVE-2026-93698, an input validation weakness in the Multilang adminbin component that could allow root-level operating system command execution. Two additional stored cross-site scripting vulnerabilities were also fixed, one of which is CVE-2026-93697 affecting the Mass Modify Accounts interface in WHM. Successful exploitation of the XSS flaws could let low-privileged accounts hijack administrator sessions. The updates were made available on September 29, 2026, and carry CVSS v3.0 base scores reaching 9.9.
Top Cybersecurity Stories: SharePoint Exploits Warned by US Authorities, Citrix and WordPress Flaws Lead Weekly Rankings
Security NEXT has published its weekly ranking of the most viewed articles from September 27 to October 3, 2026, highlighting critical vulnerability disclosures and confirmed exploitation cases. US authorities issued warnings about active exploitation of five vulnerabilities affecting SharePoint and WordPress. Citrix NetScaler received multiple vulnerability advisories with two flaws already confirmed as exploited in the wild. Apple released iOS 26.7.1 to address vulnerabilities potentially used in targeted attacks against specific individuals. Other notable incidents include a personal data breach at Times Car car-sharing service and a ransomware attack impacting Keio Electric Railway operations.
Google Releases Chrome Update Fixing 11 Vulnerabilities Including Critical WebGL Flaw
Google has issued an update for its Chrome browser that addresses 11 security vulnerabilities across Windows, macOS, and Linux platforms. The release includes Chrome 154.0.8037.98 and 154.0.8037.97 for Windows and macOS, along with version 154.0.8037.97 for Linux. One vulnerability, CVE-2026-103628, received a Critical rating due to an out-of-bounds memory write in WebGL that was originally reported in August. Nine additional issues rated High severity affect components such as FileSystem, Compositing, Skia, FedCM, SVG, MediaStream, and WebRTC, including a buffer overflow tracked as CVE-2026-103631. The update also resolves a type confusion flaw in the V8 scripting engine and one Medium-severity issue. Google plans a gradual rollout over the coming days and weeks.